6 unchanged sentences
Our enterprise risk management framework considers cybersecurity risk alongside other company risks as part of our overall risk assessment process.
−Removed: Our enterprise risk management team collaborates with our Information Security function, led by the Company’s Chief Strategy and
−Removed: Transformation Officer and the Company’s Chief Information Security Officer, to gather insights for identifying, assessing and managing cybersecurity threat risks, their severity, and potential mitigations.
+Added: Our enterprise risk management team collaborates with our Information Security function, led by the Company’s Chief Strategy and Transformation Officer and the Company’s Chief Information Security Officer, to gather insights for identifying, assessing and managing cybersecurity threat risks, their severity, and potential mitigations.
We assess PepsiCo’s Information Security program using an industry-leading cybersecurity framework from the National Institute of Standards and Technology.
4 unchanged sentences
We proactively evaluate the cybersecurity risk of a third party by utilizing a repository of risk assessments, external monitoring sources, threat intelligence and predictive analytics to better inform PepsiCo during contracting and vendor selection processes.
−Removed: Additionally, when third party risks are identified, we require those third parties to agree by contract to implement appropriate security controls.
+Added: Additionally, we require those third parties to agree by contract to implement appropriate security controls.
Security issues are documented and tracked and periodic monitoring is conducted for third parties in order to mitigate risk.
3 unchanged sentences
We also maintain insurance coverage that, subject to its terms and conditions, is intended to address costs associated with certain aspects of cyber incidents and information systems failures.
−Removed: Based on the information we have as of the date of this Form 10-K, we do not believe any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: Based on the information we have as of the date of this Form 10-K, we do not believe any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially
+Added: affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
See “Item 1A.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.